Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,152GitHub PoC 15,158VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
24,460 exploits
Exploit-DB
Satellian 1.12 - Remote Code Execution
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open ↗Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows T
35RISK
open ↗Exploit-DB
XMLBlueprint 16.191112 - XML External Entity Injection
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RISK
open ↗Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RISK
open ↗Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RISK
open ↗Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISK
open ↗Exploit-DB
Microsoft Windows Kernel - Information Disclosure
Windows Kernel Information Disclosure Vulnerability
33RISK
open ↗Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISK
open ↗Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗Exploit-DB✓ VexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open ↗Exploit-DB✓ VexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
38RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗Exploit-DB
qdPM 9.1 - Remote Code Execution
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open ↗Exploit-DB
Ricoh Printer Drivers - Local Privilege Escalation
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISK
open ↗Exploit-DB
Citrix XenMobile Server 10.8 - XML External Entity Injection
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor
23RISK
open ↗Exploit-DB
Microsoft SharePoint - Deserialization Remote Code Execution
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open ↗Exploit-DB
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISK
open ↗Exploit-DB
Easy XML Editor 1.7.8 - XML External Entity Injection
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISK
open ↗Exploit-DB
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RISK
open ↗Exploit-DB
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗Exploit-DB
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn
23RISK
open ↗Exploit-DB✓ VexDay Proof
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open ↗Exploit-DB
Microsoft Windows - CryptoAPI (Crypt32.dll) Elliptic Curve Cryptography (ECC) Spoof Code-Signing Certificate
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗Exploit-DB✓ VexDay Proof
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RISK
open ↗Exploit-DB
Digi AnywhereUSB 14 - Reflective Cross-Site Scripting
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.